Commit Graph

450 Commits

Author SHA1 Message Date
Nasreddine Bencherchali e230acd7ed Merge PR #4427 from @nasbench - Multiple Fixes & Enhancements
new: Application Terminated Via Wmic.EXE
new: Browser Execution In Headless Mode
new: Chromium Browser Headless Execution To Mockbin Like Site
new: DarkGate User Created Via Net.EXE
new: DMP/HDMP File Creation
new: Malicious Driver Load
new: Malicious Driver Load By Name
new: Potentially Suspicious DMP/HDMP File Creation
new: Remote DLL Load Via Rundll32.EXE
new: Renamed CURL.EXE Execution
new: Vulnerable Driver Load
new: Vulnerable Driver Load By Name
update: 7Zip Compressing Dump Files - Increase coverage
update: Amsi.DLL Loaded Via LOLBIN Process - Reduce level to `medium`
update: COM Hijack via Sdclt - Fix Logic
update: Copy .DMP/.DUMP Files From Remote Share Via Cmd.EXE - Increase coverage
update: Creation of an Executable by an Executable - Fix FP
update: DLL Load By System Process From Suspicious Locations - Reduce level to `medium`
update: DNS Query Request By Regsvr32.EXE - Reduce level to `medium`
update: DNS Query To MEGA Hosting Website - DNS Client - Update title and reduce level to `medium`
update: DNS Query To MEGA Hosting Website - Reduce level to `low` and update metadata
update: DNS Query To Remote Access Software Domain From Non-Browser App - Increase coverage with new domains
update: DNS Query To Ufile.io - DNS Client - Update title and reduce level to `low`
update: DNS Query To Ufile.io - Update title and reduce level to `low`
update: DNS Query Tor .Onion Address - Sysmon - Update title
update: DNS Server Discovery Via LDAP Query - Reduce level to `low` and update FP filters
update: DriverQuery.EXE Execution - Increase coverage
update: File Download From Browser Process Via Inline Link
update: Greedy File Deletion Using Del - Increase coverage
update: Leviathan Registry Key Activity - Fix logic
update: Network Connection Initiated By Regsvr32.EXE - Reduce level to `medium` and metadata update
update: Non Interactive PowerShell Process Spawned - Increase coverage
update: OceanLotus Registry Activity - Fix Logic
update: Office Application Startup - Office Test - Fix Logic
update: OneNote Attachment File Dropped In Suspicious Location - Fix FP
update: Potential Dead Drop Resolvers - Increase coverage with new domains
update: Potential Persistence Via COM Hijacking From Suspicious Locations - Increase coverage and fix logic
update: Potential Persistence Via COM Search Order Hijacking - Fix Logic
update: Potential Process Hollowing Activity - Update FP filters
update: Potential Recon Activity Using DriverQuery.EXE - Increase coverage
update: Potential Unquoted Service Path Reconnaissance Via Wmic.EXE - Reduce level to `medium`
update: Potentially Suspicious Event Viewer Child Process - Update metadata
update: PowerShell Initiated Network Connection - Update description
update: PowerShell Module File Created By Non-PowerShell Process - Fix FP
update: PsExec Tool Execution From Suspicious Locations - PipeName - Reduce level to `medium`
update: Python Image Load By Non-Python Process - Update description and title
update: Python Initiated Connection - Update FP filter
update: Remote Thread Creation By Uncommon Source Image - Update FP filter
update: Renamed AutoIt Execution - Increase coverage
update: Suspicious Chromium Browser Instance Executed With Custom Extensions - Increase coverage
update: Suspicious WebDav Client Execution Via Rundll32.EXE - New Title
update: Sysinternals Tools AppX Versions Execution - Reduce level to `low`
update: Sysmon Blocked Executable - Update logsource
update: UAC Bypass via Event Viewer - Fix Logic
update: UNC2452 Process Creation Patterns - Fix logic
update: Usage Of Malicious POORTRY Signed Driver - Deprecated
update: Vulnerable AVAST Anti Rootkit Driver Load - Deprecated
update: Vulnerable Dell BIOS Update Driver Load - Deprecated
update: Vulnerable Driver Load By Name - Deprecated
update: Vulnerable GIGABYTE Driver Load - Deprecated
update: Vulnerable HW Driver Load - Deprecated
update: Vulnerable Lenovo Driver Load - Deprecated
update: WebDav Client Execution Via Rundll32.EXE
update: Windows Update Error - Reduce level to `informational` and status to `stable`
update: Winrar Compressing Dump Files - Increase Coverage

---------

Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
2023-10-04 19:06:57 +02:00
Nasreddine Bencherchali bdffe3a7fe Merge PR #4406 from @nasbench - Multiple Updates & Additions
new: CVE-2023-38331 Exploitation Attempt - Suspicious Double Extension File
new: CVE-2023-38331 Exploitation Attempt - Suspicious WinRAR Child Process
new: CVE-2023-40477 Potential Exploitation - .REV File Creation
new: CVE-2023-40477 Potential Exploitation - WinRAR Application Crash
new: IcedID Malware Suspicious Single Digit DLL Execution Via Rundll32
new: IE ZoneMap Setting Downgraded To MyComputer Zone For HTTP Protocols
new: IE ZoneMap Setting Downgraded To MyComputer Zone For HTTP Protocols Via CLI
new: LOL-Binary Copied From System Directory
new: LSASS Dump Keyword In CommandLine
new: Old TLS1.0/TLS1.1 Protocol Version Enabled
new: Potentially Suspicious Child Process Of WinRAR.EXE
new: VMMap Signed Dbghelp.DLL Potential Sideloading
update: 7Zip Compressing Dump Files - Reduce level
update: LOLBIN Execution From Abnormal Drive
update: LSASS Memory Dump File Creation - Deprecated
update: Potential Browser Data Stealing - Increase coverage with more browsers
update: Potentially Suspicious Compression Tool Parameters
update: Potentially Suspicious Windows App Activity - Fix FP, increase coverage and reduce level
update: Rundll32 Execution Without CommandLine Parameters - Add CLI variations
update: Suspicious Child Process Of Manage Engine ServiceDesk
update: Suspicious Copy From or To System Directory - Add new folder "WinSxS"
update: VMMap Unsigned Dbghelp.DLL Potential Sideloading
update: Winrar Execution in Non-Standard Folder
update: Wscript Execution from Non C Drive - Deprecated

---------

Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
2023-09-07 11:42:15 +02:00
Nasreddine Bencherchali 360475d6ff fix: apply suggestions from code review
Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
2023-08-18 15:15:26 +02:00
Nasreddine Bencherchali 2e9bba557d feat: add mfdetours unsigned sideload 2023-08-14 09:43:11 +02:00
Nasreddine Bencherchali fff8191d65 Merge pull request #4377 from nasbench/new-rules-august-23
feat: new rules & updates
2023-08-10 11:56:34 +02:00
Nasreddine Bencherchali a13206f28b Merge pull request #4316 from swachchhanda000/master 2023-08-09 14:39:31 +02:00
Nasreddine Bencherchali 87b94ac166 feat: updates and enhancements 2023-08-08 21:53:37 +02:00
Nasreddine Bencherchali f52cd142e3 feat: rules update 2023-08-07 16:09:21 +02:00
Nasreddine Bencherchali 30933109cd feat: more updates 2023-08-03 18:50:16 +02:00
Swachchhanda Shrawan Poudel a3f2c762f5 Merge branch 'SigmaHQ:master' into master 2023-08-02 11:36:11 +05:45
Nasreddine Bencherchali e69daf27a1 fix: apply suggestions from code review
Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
2023-07-31 12:28:34 +02:00
Nasreddine Bencherchali 8dca7aa1ba feat: more updates 2023-07-28 14:32:57 +02:00
Nasreddine Bencherchali e1d07780b3 fix: fp 2023-07-24 14:08:45 +02:00
Nasreddine Bencherchali a97c96aacc fix: fp 2023-07-24 11:01:02 +02:00
Nasreddine Bencherchali db9214e8d2 fix: typos 2023-07-20 14:13:13 +02:00
Nasreddine Bencherchali 73f44e61d1 feat: add more rules 2023-07-20 13:47:30 +02:00
Nasreddine Bencherchali ccec820a01 feat: new rules & updates (#4328) 2023-07-13 10:01:05 +02:00
Ryan Plas cda0fbff62 fix:F multiple 404 links in references (#4332) 2023-06-26 10:10:04 +01:00
Swachchhanda Poudel f99229ff78 Added filter to reduce false-positives from legitimate processes 2023-06-16 10:26:58 +05:45
phantinuss a5fc65e966 fix: wording 2023-06-15 09:14:33 +02:00
Nasreddine Bencherchali a5528ac5c0 chore: update description 2023-06-14 19:48:43 +02:00
Mohamed Ashraf ea47090c2d Update image_load_side_load_waveedit.yml 2023-06-14 18:59:48 +03:00
Mohamed Ashraf (X__Junior) df8d8240c8 Create image_load_side_load_waveedit.yml 2023-06-14 18:51:16 +03:00
Nasreddine Bencherchali 9c3e652693 Merge pull request #4301 from tr0mb1r/master
feat: add new rules related to ClickOnce abuse
2023-06-13 11:29:25 +02:00
Nasreddine Bencherchali 7ecbf44bf6 feat: update clickonce rules 2023-06-12 23:52:40 +02:00
Nasreddine Bencherchali 6469462092 fix: fp found in testing 2023-06-12 00:41:36 +02:00
Nasreddine Bencherchali f963525e82 chore: update filters and metadata 2023-06-12 00:34:04 +02:00
Nasreddine Bencherchali a387b37a50 Rename image_load_side_load_RjvPlatform_2.yml to image_load_side_load_RjvPlatform_2.yml 2023-06-12 00:22:07 +02:00
Nasreddine Bencherchali 0a1fe0ebcd chore: rename file - remove space 2023-06-12 00:21:52 +02:00
Mohamed Ashraf dd95695a0f Update image_load_side_load_edputil.yml 2023-06-09 20:37:59 +03:00
Mohamed Ashraf (X__Junior) dce3b11669 multiple dll sideloading rules 2023-06-09 20:35:44 +03:00
tr0mb1r f0fd1930ba Update image_load_clickonce_unsigned_module_loaded.yml 2023-06-08 09:57:01 +04:00
tr0mb1r 47613199bd Update image_load_clickonce_unsigned_module_loaded.yml 2023-06-08 09:41:36 +04:00
tr0mb1r 4faa757e3c ClickOnce rule added
Unsigned Module Loaded by ClickOnce Application added, based on the article:
https://posts.specterops.io/less-smartscreen-more-caffeine-ab-using-clickonce-for-trusted-code-execution-1446ea8051c5
2023-06-08 09:24:42 +04:00
Nasreddine Bencherchali b11bd352bb Merge branch 'SigmaHQ:master' into rules-update-31-05-23 2023-06-02 15:50:33 +02:00
Mohamed Ashraf 9b2c23c4bf feat: add new rule for "SmadHook.dll" potential sideloading (#4282) 2023-06-02 10:58:42 +02:00
Nasreddine Bencherchali 0c75470412 chore: fix fp found in testing 2023-06-01 23:35:57 +02:00
Nasreddine Bencherchali 02526cd41b feat: more updates 2023-06-01 23:22:35 +02:00
Nasreddine Bencherchali 2453982499 feat: fix issues and fp filters 2023-05-31 17:10:24 +02:00
phantinuss 08861cb9dd fix: FPs in testing environment 2023-05-23 12:24:01 +02:00
Nasreddine Bencherchali 9d8b6def0a fix: typo in fp 2023-05-20 22:48:22 +02:00
Nasreddine Bencherchali e593068ab7 fix: fp with goopdate 2023-05-20 22:38:06 +02:00
Nasreddine Bencherchali 0ca45bf32c chore: update metadata and filter 2023-05-18 22:33:35 +02:00
Mohamed Ashraf (X__Junior) 1ea6e7390a Create image_load_side_load_wwlib.yml 2023-05-18 10:12:15 +03:00
Nasreddine Bencherchali 62caac4708 feat: multiple updates and new rules (#4242) 2023-05-17 17:21:59 +02:00
phantinuss 06ec405ce7 fix: specify image and loaded image 2023-05-16 15:37:13 +02:00
phantinuss 9da42e4b52 fix: FP with CheckPoint SmartConsole 2023-05-16 09:38:53 +02:00
Mohamed Ashraf 37bba95e4a feat: new rule related to roboform dll sideloading (#4230) 2023-05-15 16:36:53 +02:00
Nasreddine Bencherchali 0cb01970e7 feat: new rules, updates and goofy guineapig stuff (#4229) 2023-05-15 15:53:39 +02:00
Nasreddine Bencherchali e0a2d52671 Merge pull request #4218 from nasbench/fin7-rules
feat: updates and new rules related to fin7
2023-05-09 16:14:26 +02:00